Your message dated Sat, 12 Apr 2008 09:32:42 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#475163: fixed in sympa 5.3.4-4
has caused the Debian Bug report #475163,
regarding sympa: CVE-2008-1648 denial of service via crafted email
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)
--
475163: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475163
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
--- Begin Message ---
Package: sympa
Severity: grave
Tags: security patch
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for sympa.
CVE-2008-1648[0]:
| Sympa before 5.4 allows remote attackers to cause a denial of service
| (daemon crash) via an e-mail message with a malformed value of the
| Content-Type header and unspecified other headers. NOTE: some of these
| details are obtained from third party information.
First apply this patch:
http://sourcesup.cru.fr/cgi/viewvc.cgi/trunk/src/PlainDigest.pm?r1=3597&r2=4834&view=patch
and then this patch:
http://sourcesup.cru.fr/cgi/viewvc.cgi/trunk/src/PlainDigest.pm?r1=4834&r2=4835&view=patch
to fix the problem.
If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1648
http://security-tracker.debian.net/tracker/CVE-2008-1648
--
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
pgp1wOoVjcjOy.pgp
Description: PGP signature
--- End Message ---
--- Begin Message ---
Source: sympa
Source-Version: 5.3.4-4
We believe that the bug you reported is fixed in the latest version of
sympa, which is due to be installed in the Debian FTP archive:
sympa_5.3.4-4.diff.gz
to pool/main/s/sympa/sympa_5.3.4-4.diff.gz
sympa_5.3.4-4.dsc
to pool/main/s/sympa/sympa_5.3.4-4.dsc
sympa_5.3.4-4_i386.deb
to pool/main/s/sympa/sympa_5.3.4-4_i386.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Stefan Hornburg (Racke) <[EMAIL PROTECTED]> (supplier of updated sympa package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Fri, 11 Apr 2008 22:22:31 +0200
Source: sympa
Binary: sympa
Architecture: source i386
Version: 5.3.4-4
Distribution: unstable
Urgency: high
Maintainer: Stefan Hornburg (Racke) <[EMAIL PROTECTED]>
Changed-By: Stefan Hornburg (Racke) <[EMAIL PROTECTED]>
Description:
sympa - Modern mailing list manager
Closes: 472524 472941 475163
Changes:
sympa (5.3.4-4) unstable; urgency=high
.
* fix denial of service via crafted email (Closes: #475163,
CVE-2008-1648, thanks to Nico Golde <[EMAIL PROTECTED]> for the report)
* ensure that supported_lang always contains en_US (Closes: #472941,
thanks to Chris Davies <[EMAIL PROTECTED]> for the report)
* move call to Debconf library to the top of postinst (Closes: #472524,
thanks to Olivier Berger <[EMAIL PROTECTED]> for the
report and the patch)
* correct invocation of clean targets
Checksums-Sha1:
b7474900c1601fe78d348d54a2ee0efe7ebbf5bb 976 sympa_5.3.4-4.dsc
05c29c9137204d950a670f137b19d1af61b2787a 109093 sympa_5.3.4-4.diff.gz
1a90d4c47147546efd5bbc392fcc0f09c5998e8b 3086098 sympa_5.3.4-4_i386.deb
Checksums-Sha256:
802d865b6113554471ba11873bee2dfb0a2a2a05433d32a3e21e1009fcc1326b 976
sympa_5.3.4-4.dsc
0541ea71b6aab9dbcb25ce15b6e68202c6111f7b8be5e859d880ea52508c9804 109093
sympa_5.3.4-4.diff.gz
918c85d48b75538611b50709dc83a0ea471f18810937449f0eb06317c9fd1ea2 3086098
sympa_5.3.4-4_i386.deb
Files:
12518253351045796dd381f16a2986ed 976 mail optional sympa_5.3.4-4.dsc
8fb79e868bd2b75a2af6e73d0f20386f 109093 mail optional sympa_5.3.4-4.diff.gz
2447b013c561944e8da94d48fb538ab9 3086098 mail optional sympa_5.3.4-4_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFIAH8GjgVfE5tya3ERAmpZAKCae2ekvXvYkrupOWaebgSMvOSoPACg3SbT
7lzj3vPFmdqiyMks5RrTgTo=
=vMZQ
-----END PGP SIGNATURE-----
--- End Message ---